
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28888 is a race condition vulnerability in the CUPS (Common Unix Printing System) component of Apple macOS that allows a local app to gain root privileges through improper state synchronization. It was discovered by Andreas Jaegersberger and Ro Achterberg of Nosebeard Labs and disclosed on March 24, 2026, as part of Apple's March 2026 security update batch. Affected versions include macOS Sonoma prior to 14.8.5, macOS Sequoia prior to 15.7.5, and macOS Tahoe prior to 26.4. The vulnerability carries a CVSS v3.1 base score of 5.1 (Medium), reflecting its local attack vector and high attack complexity (Apple Tahoe Advisory, Apple Sequoia Advisory, Apple Sonoma Advisory).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition), specifically within the CUPS printing subsystem on macOS. The flaw arises from inadequate state handling during concurrent operations, where a malicious app can win a race condition to manipulate shared state and escalate its privileges to root. Exploitation requires local access and the ability to execute an application on the target system, and the high attack complexity (AC:H) indicates that the race window must be reliably triggered. Apple addressed the issue with improved state handling in the patched releases (Apple Tahoe Advisory, Apple Sequoia Advisory, Apple Sonoma Advisory).
Successful exploitation allows a locally-executed app to escalate privileges to root on the affected macOS system, granting full administrative control. This could enable an attacker to install malware, modify system files, access all user data, disable security controls, or establish persistent backdoors. While the attack is limited to local access (no remote exploitation), root-level compromise on a macOS endpoint significantly increases the risk of lateral movement within enterprise environments and complete data exposure (Apple Tahoe Advisory, Apple Sequoia Advisory).
/var/log/cups/ showing unusual or repeated print job submissions from non-standard applications; system logs (/var/log/system.log) showing privilege escalation events or unexpected root-level process spawning.cupsd or CUPS-related processes with elevated privileges./etc/, /usr/, /Library/) created or altered by a non-root user's application; unexpected cron jobs, launch agents, or launch daemons added under /Library/LaunchDaemons/.Apple has released patches addressing this vulnerability in macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4, all released on March 24, 2026. Users should update their macOS systems to these versions or later immediately via System Settings > General > Software Update. No configuration-based workaround has been published by Apple; upgrading to a patched version is the only recommended remediation. Organizations should also monitor for suspicious application behavior and restrict the installation of untrusted applications as a defense-in-depth measure (Apple Tahoe Advisory, Apple Sequoia Advisory, Apple Sonoma Advisory).
The vulnerability was part of a large March 2026 Apple security update that patched over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS, which received broad coverage from security news outlets (BeyondMachines). The SANS Internet Storm Center also noted the update batch (SANS ISC). The CIS issued an advisory noting that multiple vulnerabilities in Apple products could allow for privilege escalation (CIS Advisory). No specific high-profile researcher commentary focused exclusively on CVE-2026-28888 has been identified beyond the discoverers' credit in Apple's advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."